Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 155

github логотип

GHSA-jrcp-c39h-r29x

больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-w7cg-5969-678w

больше 3 лет назад

Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-wfvx-wr33-m97w

больше 3 лет назад

The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to obtain sensitive information or gain root privileges via a symlink attack on the Catalina localhost directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43v2-6grp-9pp9

больше 3 лет назад

Apache Tomcat does not enforce the maxHttpHeaderSize limit

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-mg4v-rf8p-ghqq

больше 3 лет назад

Apache Tomcat allows remote attackers to bypass intended access restrictions

EPSS: Средний
github логотип

GHSA-p26v-97vp-jcx6

больше 3 лет назад

Access controll bypass in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-3xpj-jgv5-q4vv

больше 3 лет назад

Access restriction bypass in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-8c5c-v572-37xf

больше 3 лет назад

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before 7.0.52-1ubuntu0.7 on Ubuntu 14.04 LTS, and tomcat8 and libtomcat8-java packages before 8.0.32-1ubuntu1.2 on Ubuntu 16.04 LTS allows local users with access to the tomcat account to gain root privileges via a symlink attack on the Catalina log file, as demonstrated by /var/log/tomcat7/catalina.out.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-c78g-qwpw-2jgv

больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
github логотип

GHSA-pvjh-7h8q-q56r

больше 3 лет назад

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-jrcp-c39h-r29x

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

CVSS3: 8.1
39%
Средний
больше 3 лет назад
github логотип
GHSA-w7cg-5969-678w

Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token

CVSS3: 8.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-wfvx-wr33-m97w

The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to obtain sensitive information or gain root privileges via a symlink attack on the Catalina localhost directory.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43v2-6grp-9pp9

Apache Tomcat does not enforce the maxHttpHeaderSize limit

CVSS3: 7.5
17%
Средний
больше 3 лет назад
github логотип
GHSA-mg4v-rf8p-ghqq

Apache Tomcat allows remote attackers to bypass intended access restrictions

14%
Средний
больше 3 лет назад
github логотип
GHSA-p26v-97vp-jcx6

Access controll bypass in Apache Tomcat

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3xpj-jgv5-q4vv

Access restriction bypass in Apache Tomcat

2%
Низкий
больше 3 лет назад
github логотип
GHSA-8c5c-v572-37xf

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before 7.0.52-1ubuntu0.7 on Ubuntu 14.04 LTS, and tomcat8 and libtomcat8-java packages before 8.0.32-1ubuntu1.2 on Ubuntu 16.04 LTS allows local users with access to the tomcat account to gain root privileges via a symlink attack on the Catalina log file, as demonstrated by /var/log/tomcat7/catalina.out.

CVSS3: 7.8
21%
Средний
больше 3 лет назад
github логотип
GHSA-c78g-qwpw-2jgv

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

24%
Средний
больше 3 лет назад
github логотип
GHSA-pvjh-7h8q-q56r

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться